PDA

View Full Version : RPS Blachole Exploit



mpk
24-10-2011, 05:33 AM
Since this morning (um, 06:25), AVG has been reporting an "Exploit Blackhole Exploit Kit (type 2064)", filename "best-videogames.com/forum/ind.php", when I visit the RPS forums.

There's little on Google about it, but I did find this:
http://www.symantec.com/connect/blogs/blackhole-theory

Obviously, this could have come from another site, and AVG just popped up coincidentally, but I've visited the site repeatedly to check. AVG reports the danger on both Chrome and Firefox.

Anthile
24-10-2011, 05:43 AM
I'm having this as well:

http://i.imgur.com/owIe2.png

Nalano
24-10-2011, 07:29 AM
Likewise. No other site. Not even the main RPS site. Just this forum.

cwoac
24-10-2011, 08:25 AM
chrome is now reporting (parts of) the forum as malicious as well.

lhzr
24-10-2011, 09:13 AM
yeah, there's something wrong with the forum. kaspersky says it tries to connect to this address (don't click the link):

h ttp://drcooper.orge.pl/iframe.php?id=406x8gaw3trjcn1wx4kmv41roybsmal

(edited by Jams O'Donnell, trying to make the link unclickable and failing)

Jams O'Donnell
24-10-2011, 09:20 AM
How long has the RO2 ad been there? Is it new this morning? If so, that could be the culprit. Ads do sometimes make malware warnings go off.

Grizzly
24-10-2011, 09:22 AM
How long has the RO2 ad been there? Is it new this morning? If so, that could be the culprit. Ads do sometimes make malware warnings go off.

The add ont he ffront page is BF3 one. The Red Orchastra one has been here for a looong time.

Jams O'Donnell
24-10-2011, 09:28 AM
Culprit located and eliminated for now. Please post here if you're still seeing issues.

lhzr
24-10-2011, 11:17 AM
seems fine now, thanks jams.
what was the problem, an infected ad? how do these things happen?

Jams O'Donnell
24-10-2011, 11:30 AM
Not actually sure where it came from, which I do not like.

Rossignol
24-10-2011, 12:32 PM
Possibly a vBulletin hack of some kind. Seems fixed for now.

Nalano
24-10-2011, 04:44 PM
Whatever you did, it worked. No longer is AVG complaining to me.

mpk
24-10-2011, 05:27 PM
Braw. All good here too.

My spelling is obviously not the greatest at stupid o'clock in the morning. On top of the new, Scottish version of the blackhole, the email I fired off to Jim bounced back as apparently you spell rck with an "o". Oh well.